CentOS PAM+LDAP authentication and profile's host attribute

I have a system with CentOS 6.3, openldap + PAM-auth installed. Everything works well.

But after turning pam_check_host_attr to yes, all LDAP-auths fail with message "Access denied for this host".

1. hostname on the server returns correct value, the same value is listed in user's profile.
2. "pam_check_host_attr no" works fine and allows everyone with correct uid/password
3. a piece of /var/log/secure: